Sobre este puesto de Deputy CISO en Deepwatch
Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry. If you're ready to challenge yourself with work that matters, then this is the place for you. We're redefining cybersecurity as one of the fastest growing companies in the U.S. – and we have a blast doing it!
Who We Are
Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business.
Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit.
Deepwatch recognition includes:
- 2025, 2024, 2023, 2022 and 2021 Great Place to Work® Certified
- 2026, 2025, 2024, 2023, 2022 Forbes America's Best Startup Employers
- 2025 Cybersecurity Breakthrough Award: Managed Security Solution of the Year
- 2025 CRN Security 100 - Top 20 Endpoint and Managed Security Companies
- 2024 Military Times Best for Vets Employers
- 2024 US Department of Labor Hire Vets Gold Award
- 2024 Cyber Defense Magazine, Global Infosec Awards
- 2023 LinkedIn Top 50 Startups
- 2023 InHerSight #1 Cyber Workplace for Women
- 2023 and 2022 Fortress Cybersecurity Award
- Backed by premier investors with >$275 Million in growth capital from Goldman Sachs, Vista Equity Partners, Springcoast, Splunk Ventures, and ABS Capital
Reports To: Chief Information Security Officer
Department: Information Security
Location: Remote, EST timezone preferred
The Deputy Chief Information Security Officer will serve as the CISO’s senior operating partner and second-in-command for the Information Security organization. This person will help run the department day-to-day, drive execution across security, IT, cloud, compliance, privacy, and risk workstreams, and ensure the security program is organized, measurable, accountable, and aligned with business needs.
This is a highly hands-on leadership role. The Deputy CISO will be expected to lead teams, make decisions, run operating rhythms, manage 1:1s and team meetings, track project execution, rebuild and mature the security program, and represent the department across the business. The ideal candidate is a strong security leader and operator who can move between executive strategy, technical detail, people leadership, audit readiness, incident response, and project execution without needing constant direction.
This person will report directly to the CISO and will be trusted to act on behalf of the CISO in key meetings, decisions, escalations, and cross-functional workstreams.
Department Leadership and Operations:
- Run the day-to-day operating cadence of the department, including team meetings, leadership meetings, 1:1s, project reviews, status reporting, and executive updates.
- Lead, mentor, and develop security, IT, cloud, compliance, and risk team members as assigned.
- Build a high-performing, accountable, execution-focused culture across the security organization.
- Represent the security organization with executives, customers, auditors, legal, privacy, engineering, product, IT, and business stakeholders.
- Ensure the CISO has clear visibility into department performance, project health, risks, blockers, resource needs, and key decisions.
- Develop and refine security strategy in alignment with business goals, customer expectations, regulatory requirements, and industry best practices.
- Establish measurable security outcomes, KPIs, dashboards, QBRs, and executive reporting that show progress, risk, and business value.
- Drive maturity across vulnerability management, incident response, identity and access management, endpoint security, cloud security, MDR/SOC operations, GRC, IT operations, and security engineering.
- Drive projects from intake through completion with clear owners, deadlines, milestones, dependencies, decisions, risks, and next steps.
- Maintain accurate project tracking, dashboards, Jira/Confluence hygiene, timelines, meeting notes, and executive summaries.
- Hold project owners accountable for commitments, updates, deadlines, and follow-through.
- Lead internal and external audit readiness, response, evidence collection, remediation, and ongoing compliance activities.
- Oversee compliance programs and control frameworks such as SOC 2, ISO 27001, ISO 42001.
- Partner with Legal, Privacy, Finance, IT, Engineering, Product, and business leaders to align governance activities with company objectives.
- Help run or mature the risk committee and ensure organizational risks are identified, documented, prioritized, tracked, and remediated.
- Maintain policies, standards, procedures, and controls that protect company and customer data.
- Serve as a key liaison with auditors, customers, regulators, vendors, and internal stakeholders.
- Lead incident response activities, ensuring timely coordination, communication, containment, recovery, and post-incident improvement.
- Conduct and oversee risk assessments, threat modeling, vulnerability management, and security reviews.
- Guide secure cloud architecture and governance across AWS, Azure, GCP, or similar cloud environments.
- Evaluate tools, vendors, services, and resourcing needs to support the security program.
- Drive continuous improvement through automation, better workflows, stronger documentation, and clearer accountability.
Required Qualifications:
- 10+ years of progressive experience across cybersecurity, IT, security operations, cloud security, compliance, risk, or related technical leadership roles.
- 5+ years of people leadership experience, including managing teams, leaders, 1:1s, performance expectations, and department operating rhythms.
- Proven ability to run a security department or major security program with minimal supervision.
- Strong hands-on understanding of security, IT, cloud, compliance, privacy, and risk operating models.
- Experience rebuilding or maturing a security program, including controls, processes, metrics, governance, and reporting.
- Demonstrated experience managing audits, compliance programs, evidence collection, control tracking, remediation, and executive communication.
- Strong project and program execution skills, including ownership of deadlines, dependencies, priorities, blockers, and cross-functional follow-through.
- Ability to communicate complex security and risk topics clearly to technical, non-technical, executive, customer, and board-level audiences.
- Experience partnering with Legal, Privacy, Product, Engineering, IT, Finance, Sales, Customer Success, and executive leadership.
- Strong judgment, discretion, urgency, ownership, and ability to make decisions in ambiguous situations.
- Experience with Jira, Confluence, dashboards, executive reporting, QBRs, and operational metrics.
Preferred Qualifications:
- Experience in SaaS, cloud-first, managed security services, MDR, or technology-driven environments.
- Deep experience with frameworks and standards such as SOC 2, ISO 27001, PCI, HIPAA, NIST, GDPR, CCPA, and ISO 42001.
- Experience with cloud security architecture and governance across AWS, Azure, or GCP.
- Familiarity with GRC platforms, ServiceNow, SIEM, EDR, vulnerability management platforms, identity platforms, and security operations tooling.
- Strong financial acumen, including budget planning, vendor management, resource planning, and headcount planning.
- Prior experience as a Deputy CISO, Director of Security, VP of Security, or Head of Security Operations.
What Success Looks Like:
- The CISO has a trusted second-in-command who can run the department, drive decisions, and keep work moving.
- The department has clear priorities, ownership, operating rhythms, metrics, and accountability.
- Security, IT, cloud, compliance, privacy, and risk workstreams are visible, organized, and progressing.
- Projects have clear owners, timelines, status, blockers, decisions, and next steps.
- Team meetings and 1:1s are consistent, productive, and tied to execution.
- Audits, compliance activities, and risk remediation are well-managed and predictable.
- The security program becomes more mature, measurable, automated, and business-aligned.
- Executives and business partners view security as a trusted, decisive, and effective partner.
- The CISO gets time back to focus on enterprise risk, customer trust, product strategy, executive leadership, and long-term security direction.
Ideal Candidate Profile:
The ideal candidate is a senior security operator who has lived inside complex security programs and knows how the work actually gets done. They are technical enough to challenge engineers, operational enough to drive execution, and executive enough to represent the department across the business.They are organized, direct, accountable, calm under pressure, and comfortable making decisions. They can sit in a room with technical teams, understand the real issue, identify the gap, document the outcome, assign the next step, and make sure it gets done.This is not a purely advisory role. This is a hands-on leadership role for someone who wants to help build, run, and mature the operating system of a modern security organization.
Statutory Pay Disclosure:
The anticipated base salary range for this role is $200,000 - $215,000 + bonus + stock options + benefits. Actual compensation may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level.
ITAR Compliance:
This position will have access to customer data and as such is subject to International Traffic in Arms Regulations (ITAR). Upon application, candidates will be asked to confirm that they are a U.S. Person as defined by the following:
A citizen of the U.S.;
A lawful permanent resident of the United States;
A person admitted to the United States as a refugee; or
A person that has been granted asylum by the United States government.
The intent of this requirement is not to verify employment eligibility overall, but to ensure compliance with import/export regulations. If you do not meet these requirements, we encourage you to apply for other open roles at Deepwatch. This information will be verified upon offer of employment.
What We Offer:
Deepwatch is excited to provide benefits designed to support team members and their families. Including:
- Medical, dental, vision, and disability insurance
- Flexible Time Off (FTO), 12 company holidays, sick leave and 8-Weeks Paid Parental Leave
- Unique professional development benefits with Annual “development dollars” to support our people growth and development
- Wellness contests and monthly educational programs
- 401(K) retirement program
- Learn more here: Deepwatch Benefits
We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you. Please review our DEI Statement here.
- Be interested in and able to work remotely from a home office when not at a corporate office
- Pass a pre-employment background check in accordance with applicable laws
Deepwatch is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, marital status, sexual orientation, gender identity, genetic information, protected veteran status, or any other characteristic protected by law. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.
By submitting your application, you agree that Deepwatch may collect your personal data for recruiting, global organization planning, and related purposes. The Deepwatch Privacy Policy explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over Deepwatch’s use of your personal information.